CRITICAL
9.9 CVE-2026-77240 Published 18 Sept 2026
WACRM Self-Promotion & Tenant Access Vulnerability
Worried this affects your website?
WACRM, a self-hostable CRM template for WhatsApp, is affected.
In versions 0.7.0 and earlier, authenticated users can modify their own account role and ID, allowing self-promotion or access to other tenants' resources.
Additionally, certain knowledge-base chunks can be read by authenticated non-members of another tenant.
Reference: CVE-2026-77240 on NVD
← Back to Security News